ThunderX
Aliases: Ranzy Locker
- First seen
- 2021-06-15 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 13:44:10
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications
Targeted regions: country_code:us country_code:de country_code:fr
Context
ThunderX, also known as Ranzy Locker, is a strain of ransomware that targets organizations in various sectors. It typically encrypts the victim's files and demands a ransom for decryption keys.
Detection coverage
- 2 YARA rules
Detection rules
- ARKBIRD_SOLG_Ran_Ranzy_Locker_Nov_2020_1 (yara-rule)
- MALPEDIA_Win_Thunderx_Auto (yara-rule)
Reports & references
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- public.intel471.com — Ransomware As A Service 2020 Ryuk Maze Revil Egregor Doppelpaymer (report)
- cyborgsecurity.com — Hunting Ransomware Inhibiting System Backup Or Recovery (report)
- Mandiant — Chasing Avaddon Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Thunderx (report)
- labs.sentinelone.com — Ranzy Ransomware Better Encryption Among New Features Of Thunderx Derivative (report)
- picussecurity.com — A Detailed Walkthrough Of Ranzy Locker Ransomware Ttps (report)
- id-ransomware.blogspot.com — Thunderx Ransomware (report)
- ic3.gov — 211026 (report)
- bleepingcomputer.com — Thunderx Ransomware Rebrands As Ranzy Locker Adds Data Leak Site (report)